What the vulnerability does
01Description
Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0.
Explanation of Vulnerability in Simple Terms
Google Analytics by Monster Insights versions up to 8.21.0 lack proper authorization checks, allowing authenticated users with low privileges to trigger a denial-of-service condition. An attacker with a valid WordPress account can make requests that degrade site availability. The vulnerability requires an existing user account but no special interaction from victims.
What an attacker can do
Degrade site availability by making authenticated requests that consume resources.
Potential impact on your site
Site performance may degrade if an authenticated user repeatedly exploits this flaw; no data theft or site takeover risk.
Conditions required to exploit
Attacker must have a valid low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities